Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
Cisco logo

CiscoCertified Network Professional Cybersecurity (CBRCOR)

Domain 2Objective 22

2.22 Describe Tools and Their Limitations for Network Analysis Such as Packet Capture Tools, Traffic Analysis Tools, Network Log Analysis Tools 350-201 Practice Questions (Page 6)

Part of the Techniques domain, which accounts for 30% of the 350-201 exam. Cisco does not publish an official question count, but from its 120-minute exam (~50–80 total, ~15–24 in this domain), expect 1–1 from this objective — we provide 44 practice questions to prepare you well beyond it. (estimate)

44questions here
9free pages
6concepts
30%of the exam

Questions 26–30

  1. 26expert · hard

    A network analyst is investigating a possible DNS tunneling attack. The analyst has access to NetFlow data, DNS server logs, and the ability to capture packets on the DNS server. The NetFlow data shows a large volume of DNS traffic to a single external server. The DNS logs show many queries with long subdomains. The analyst wants to confirm the tunneling and determine the data being exfiltrated. Which approach is most effective?

    Select an answer first
  2. 27application · medium

    A security analyst is correlating firewall logs with authentication logs to investigate a breach. The firewall logs show a connection from an internal IP to an external IP at 10:15:30, but the authentication logs show the user logged in at 10:16:45. The analyst suspects the user's account was compromised. What limitation of network log analysis tools is most likely affecting the investigation?

    Select an answer first
  3. 28expert · hard

    A security analyst is investigating a possible command-and-control (C2) communication that used a low-and-slow pattern over several days. The analyst has NetFlow data with 1:1000 sampling and full packet capture only for the last hour. Which approach is most likely to reveal the C2 communication?

    Select an answer first
  4. 29application · medium

    A security analyst is using NetFlow data to investigate a possible data exfiltration. The analyst notices that the total bytes reported by NetFlow are significantly lower than the bytes recorded by the firewall's own byte counter for the same session. What is the most likely reason for this discrepancy?

    Select an answer first
  5. 30expert · hard

    A network security team is planning to deploy a monitoring solution to detect malware infections on a high-speed (40 Gbps) backbone link. The team has the following options: full packet capture on a dedicated appliance, NetFlow export from the router, and a SIEM that collects firewall and IDS logs. The team's primary goal is to detect C2 traffic that uses encrypted protocols. Which solution is most effective for this goal?

    Select an answer first
Finished these 5 questions?

Review the revealed explanations, or continue through the curriculum.

Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Cisco. “350-201” is a trademark of its owner, used for identification only.